CVE-2019-8898

Description

An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.456

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Apple iTunes (X64) (12.10.3.1)Windows
Vulnerability CVE-2019-8898 are affected in Apple iTunes 12.10.2Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 12.10.2Windows
Multiple Vulnerabilities are affected in Apple iTunes 12.10.2Windows
Vulnerabilities CVE-2019-8835,CVE-2019-8844,CVE-2019-8846,CVE-2019-8898 are affected in Apple Safari for MAC 13.0.3Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-312126Apple iTunes (X64) (12.10.3.1)
PATCH-342816Apple iTunes (12.13.4.4)
PATCH-611604Apple Safari for MAC (MacOS Sonoma) (18.6)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234